Posted
by
Soulskillon Friday June 12, 2009 @04:13PM
from the not-enough-l33t-to-english-translators dept.

Hugh Pickens writes "Former CIA counterterrorism analyst Stephen Lee has an interesting article in the Examiner asserting that the National Security Agency is 'a secretive, hidebound culture incapable of keeping up with innovation,' with a history of disregard for privacy and civil liberties. Lee says that for most of its sixty-year history, the NSA has been geared to cracking telecom and crypto gear produced by Soviet and Chinese design bureaus, but at the end of the cold war became 'stymied by new-generation Western-engineered telephone networks and mobile technologies that were then spreading like wildfire in the developing world and former Soviet satellite countries.' When the NSA finally recognized that it needed to get better at innovation, it launched several mega-projects, tagged like 'Trailblazer' and 'Groundbreaker,' that have been spectacular failures, costing US taxpayers billions. More recently, the NY Times reported that the NSA has been breaking rules set by the Obama administration to peer even more aggressively into American citizens' phone traffic and email inboxes. Whistleblower reports portray NSA domestic eavesdropping programs as unprofessional and poorly supervised, with intercept technicians ridiculing and mishandling recordings of citizens' private 'pillow talk' conversations. Lee concludes that 'if the Federal government must play a role, then Congress and President Obama should turn to another agency without a record of creating mistrust — perhaps even a new entity. Meanwhile, NSA should focus on listening in on America's enemies, instead of being an enemy of Americans and their enterprises.'"

I read that headline, and my first question was:WTF? NSA III? What happened to NSA I and II? As a matter of fact, I never even heard about NSA II -- that must be some super-secret black ops org.

And then my second questions was:WTF? Why is NSA II wearing a suit? Is it even possible for a TLA to wear a suit? Or does "suited" mean someone brought a lawsuit against them, in which case the corollary query is "Who would sue to grant *additional* powers to a TLA?

It is not the NSA 3. It is NSA 3-suited, geesh read the title carefully, already.

Seriously though, do those with mod points not have anything better to do than mod this offtopic? Ill-suited clearly looks like III-suited in the title, and I think it probably has something to do with fonts in stylesheets, and not my default browser font.

Yea, even if they did create a new agency, the simple reality is that most of the staff would be drawn from the NSA anyway. If you're going to reform the NSA, just do it, don't just add another player with roughly the same mission to make the turf battles even worse.

I always thought the Americans loved bureaucracy and redundancy. Police, FBI, US Marshall's, NSA, Homeland Security, CIA (and probably others that haven't yet been depicted in a major motion picture); I am sure their money is well spent funding all these agencies; especially those with overlapping jurisdictions.

The mandates of the organizations you list are different enough that any redundancy created by separating them is more than worth it (The NSA might not respect the fact that they have little authority to operate against people inside the U.S., but the situation would not be better if they were part of some national policing body).

Police are local law enforcement, like the local constables in the U.K.. The FBI is the national 'detective bureau' (think "Scotland Yard"), the The U.S. Marshals are like the police, but on the national level. The Secret Service's primary job is to protect the president, vice president, and their families, and to investigate counterfeiting. The NSA consists of a bunch of computer jocks and crypto nerds breaking codes and whatnot -- they do signal intelligence. The CIA is focused international intelligen

It goes something like this: Police officer - sheriff - state trooper and then it gets split up to the US Marshalls, FBI, CIA, NSA, DHS, ATF, DEA, RIAA, MPAA, Interpol, BCBP, USCIS all whom apparently can arrest you for various reasons.

Sure, let's go ahead and create ANOTHER agency. People like Lee need to realize money doesn't grow on trees. Who else can we get to do this? The whole point is to find the next group that will try to pull something here in the US. DHS, BATFE, and FBI, all have the capability, although DHS would probably the best pick of the bunch.

The problem with the NSA is that it is part of the intelligence structure. If you insert them as a defensive player, more often than not, they will take absolutely NO action in order to protect their spying capabilities.

At present, nobody knows exactly what the reach is of the NSA. Nobody knows what they can and can't hear. If you task them with defending assets, each probe or attack reveals new information about what the NSA has at their disposal, depending on what the response is. I really don't think the NSA is willing to compromise the secrecy of its capabilities in order to thwart hackers.

Why would an agency dedicated to SPYING on other countries want the PUBLIC to use technologies such as IPSEC? They obviously understand the importance of computing security for our countries' future more than you will ever be able to comprehend.

To answer the ACs first point, because they are also responsible for defense through their Informations Assurance Directorate; If the internet becomes part of the critical infrastructure of the USA (which it probably already has) then defences like IPSEC have to be widespread standards.

The problem with the NSA is that it is part of the intelligence structure. If you insert them as a defensive player, more often than not, they will take absolutely NO action in order to protect their spying capabilities.

I'm not so sure that they would take no action. They certainly have taken actions in the past. And even if you assume that the help they offered didn't affect their best procedures, it still has an effect on the landscape in which they operate.
Having said that - you missed an even more fundamental issue. They are a part of the intelligence structure and as such will treat any problem as an intelligence issue. Some of that probably isn't a bad thing; security procedures, vulnerability assessments and m

This really deserves even more mod points than the rest. A _VERY_ good analysis. The eternal fight of CND people, getting actionable intelligence (we want to fix it yesterday, they want to see what the BG are doing and also don't want to give away how they knew to listen in the first place).

I doubt the authors claims regarding the state of the NSA. It's fun to take a poke at big agencies like the NSA because they fit into that 'big bad government' mythology that is so prevalent today. He's presuming the NSA is somehow more effective than any other large organization. (public OR private)

What I doubt is the possibility that a new agency would, in fact, respect the personal freedoms as spelled out in the constitution and probably codified with laws and court precedence. The steady corrosion of discipline and 8 years of Executive Office supremacy has worn away the last of the ideals spelled out in the Constitution.

The last new agency I can recall is the Homeland Security Agency. They were gifted all kinds of previously independent agencies. The benefits are equally unclear on all sides of that monolith.

if the Federal government must play a role, then Congress and President Obama should turn to another agency without a record of creating mistrust

Like, the FBI? Or perhaps the NRO? The CIA is just down the road. Maybe NASA could do it. Really - the facts are these - NSA already has the equipment, connections and brain power. You'll have a very difficult time replicating, much less staffing any enterprise like the NSA.

Legally, they really are disqualified from performing the role of domestic spying. After all, they're administered by DOD, they've skirted American law by utilizing foreign bases for gathering, and are well known for bending the arms of domestic telecom companies.

But they are a working tool - and they get the job done. It's difficult to argue against something that, so far, seems to work.

"But they are a working tool - and they get the job done. It's difficult to argue against something that, so far, seems to work."
What is it, exactly, that they get done? And how do you know it works?
You're turning a blind eye to a government agency with a huge amount of power that is performing illegal surveillance. I'm not nearly as trusting as you are...

It's difficult to argue against something that, so far, seems to work.

Is that a challenge?

The NSA has overstepped its bounds far too often (with or without the complicity of the AG's office or the Executive's office) that there is no justification for them to be assigned more capabilities. "Cyberdefense" or whatever you want to call it is two small letters away from "cyberoffense". And given the track record, it'd be only a matter of time before those capabilities were used against American citizens with

There's a reason they operate in total secrecy - the information the NSA gathers is largely useless for domestic security purposes. But for commercial, political and legal purposes that information could be a deadly weapon.

They're administered by the DOD. Unlike civilian operations, such as the FBI, NSA personnel very face real consequences for leaking information to the public. I don't know of any agency that has maintained such a degree of secrecy.

Here's an idea: if the NSA has gotten to the point that even the White House or Congress can't control them, cut off their funding altogether and wish their employees good luck finding jobs. Create a new, much smaller NSA that has the authority to do one thing and only one thing: handle security for other government agencies, such as setting minimum standards for TOP SECRET transmission.

Don't back a dog into a corner.. especially one with everyone's dirty secrets and vulnerabilities logged and stored away. If the NSA had to be dismantled, it would have to be slowly and in a very controlled way. No server or data device can escape or terrible things would happen.

Perhaps he is a little misguided in saying that we need to put the job in another agency's hands, but his reason for thinking so is not. I mean what we really need to do is take some power out of the NSA's hands. This is more of the mess left by the Bush Administration. They gave them so much power because of after 9/11 and the war on terrorism. It was a big problem immediately following 9/11 because we all wanted security so much we didn't realize how much we were losing. Obama is partially to blame for this when we voted to let the telcom companies off the hook last year. Perhaps it is time to give the Patriot Act the ax or rename it the Unconstitutional Act.

Any and all domestic spying for one. Their mandate as part of the DOD means something very real. If they operate domestically they are breaking the law. Of course the people responsible for oversight, our representatives, have not been doing their jobs. Oversight has been a huge problem for at least the last 8 years, Clinton actually received a fair amount due to his rabid opponents but this is actually a good thing even if it was idiots that were trying to crucify him over stupid issues. Of course it's bee

I'm guessing you're talking about warrantless wiretaps? Or are you talking about all NSA FISA intercepts? Does that include any communication as long as one "end" of the conversation is by a US citizen in the US? For instance, a call from a US citizen in the United States to a known terrorist facilitator in Pakistan. Is that domestic spying or is it international? If it's domestic, does the FBI then have jurisdiction?

The core issue was government entities going outside of their mandates and how it never leads anywhere good.

The whole question of jurisdiction just shows that clear lines need to be drawn. Any domestic activity at all on the part of the NSA is outside of their mandate and the FBI is ill-equipped to handle the situation. Do you fix the FBI? Or do you change the mandate of the NSA? Fixing the FBI will cost a lot more but safeguards the principles on which their agency was founded.

Yours points are much more fair in this post and I don't find myself disagreeing as much...however, I still think a decent hypothetical is--an American citizen places a call to a known terrorist in Pakistan. The American citizen is calling from US soil, and let's say has no previous record of contacting terrorists. Should the call be intercepted? Who should do it?

The core issue was government entities going outside of their mandates and how it never leads anywhere good.

Hah, well that's pretty much the story of the last 100 years! Are you as worried about government healthcare etc?

The whole question of jurisdiction just shows that clear lines need to be drawn. Any domestic activity at all on the part of the NSA is outside of their mandate and the FBI is ill-equipped to handle the situation. Do you fix the FBI? Or do you change the mandate of the NSA? Fixing the FBI will cost a lot more but safeguards the principles on which their agency was founded.

All this beating up on the NSA is fun and stuff, but are we really complaining that we don't have a competent domestic spying agency? We've already proven as a society to be incapable of electing a majority of leaders that respect privacy and are willing to give up a little temporary safety for essential liberty. So would it actually make us happy to have a bunch of g-men who are intelligent when it comes to new technology and could really fully exploit all the powers of databases and networks and algorithms to spy on us in an incredibly thorough manner?

That's not the complaint at all. If we had an agency actually geared for domestic cyber security, in theory, they would be able to crack down on NSA agents that have far over-reached their duties. I think it would be nice to have an agency more modeled after the FDA etc, auditing corporate networks the way FDA audits new food/drug products that are coming on to the market. If a company fails an audit, they receive a large fine, and just like the FDA does with research labs, companies need to be ready to

If you create an agency whose express purpose is monitor for suspect conversations, its only natural that they are going to try to ensure they monitor as much traffic as possible. In the case of the NSA, I am sure they can just tell a phone provider like AT&T we are going to filter your traffic, don't tell anyone or you go to jail. They have absolute undefined power as long as they are not monitored.

Actually, that's NOT their express purpose. Foreign Intelligence is not the same as domestic intelligence gathering. Look what a big deal the agency went through the last 10 years under Hayden with the limited domestic tapping they were only recently allowed to do. Lastly, who says they're not monitored?

Quidquid latine dictum sit, altum sonatur.

p.s. if you're going to try to use a latin phrase to make yourself sound more authoritative or something, you might want to get the spelling right..

And here I haven't even heard of NSA-II yet and already we're on the third one?? I've seriously got to keep up on the news! But apparently they're "Suited for Domestic Cybersecurity Role" so maybe I should relax a little.

The first is that unbreakable encryption was invented in 1917, and if it is applied with discipline can be kept unbreakable. It is called the "one-time pad." It was used in World War II for high level telephone conversations (e.g., Roosevelt to Churchill) that could not be broken today if you could have a recording of the encrypted transmissions. It has its limitations, but isn't difficult to implement, especially with modern technology.

Long story short, this guy is an idiot. I could go on at great length, but I'll just leave at this. (If anyone does want to discuss specifics in greater detail...which I'm sure they won't...I'd be happy to reply)

First, a former CIA analyst from 10+ years ago doesn't know anything about the way NSA works. "CIA analysts" are the grunts of the intelligence community...more often than not they're the ones with english and political science degrees hired right out of college after having a grand time studying abroad in Prague or Barcelona. The author of this piece not only has CIA analyst on his resume but also Army...before making the jump to become a contractor (which could be anything from a security guard to copier technician). Anyway...

Additionally, what he thinks he knows is ludicrous, and I've just picked (IMHO) the most egregious example:

Whenever I met with my NSA counterparts, it was clear that they were stymied by new-generation Western-engineered telephone networks and mobile technologies that were then spreading like wildfire in the developing world and former Soviet satellite countries.

Total nonsense. The proliferation of cellphones/satellite phones/wifi etc around the world has been one of the best things to happen to the NSA in YEARS. To claim otherwise is nutty.

the National Security Agency is 'a secretive, hidebound culture incapable of keeping up with innovation,

Yeah, right. That's why the NSA-proprietary software actually works and the rest of the DoD is "innovating" by wasting billions of dollars on contractor-developed software that doesn't work. Maybe he thinks innovation means cutting off USB ports like the Army has done?

the National Security Agency is 'a secretive, hidebound culture incapable of keeping up with innovation,

Yeah, right. That's why the NSA-proprietary software actually works and the rest of the DoD is "innovating" by wasting billions of dollars on contractor-developed software that doesn't work. Maybe he thinks innovation means cutting off USB ports like the Army has done?

And Lee just happens to work (or have worked) for such contractors. Gee, what a coincidink...

If the CIA wants the NSA to stay out of domestic security, I say they can prove it by putting their programmers where their mouth is. All I'm seeing from my point of view is the NSA doing a lot of contributing and the CIA doing a lot of bitching.

No its not. If President Obama cannot keep discipline within his NSA, then one should question his leadership. Bush had no problem trying to purge the CIA of liberals, and if Obama wanted to purge the NSA of those who would spy on American citizens, then, he would.

The real issue is that, now President Obama is in the hot seat, he is being barraged daily by a bunch of threat reports, classified and unaccountable, that he finds himself, thanks to 9/11, incapable of enti

One has to wonder how much this ex-CIA guy is just doing a hatchet job on a former interservice rival. Traditionally, CIA has been about black ops and human intelligence, and the NSA was about signals, but one wonders, just how much mission overlap is there. This, after all, a government that gives us an Army with ships and a Navy with tanks, and so on. I would be willing to bet that waving around civil liberties has just become another cynical tool that entrenched bureaucrats use to attack their rivals,